Vulnerabilities > Nagios > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-09-07 CVE-2022-38254 Cross-site Scripting vulnerability in Nagios XI
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.
network
low complexity
nagios CWE-79
6.1
2022-06-29 CVE-2022-29269 Cross-site Scripting vulnerability in Nagios XI
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
network
low complexity
nagios CWE-79
6.5
2022-06-29 CVE-2022-29270 Missing Authentication for Critical Function vulnerability in Nagios XI
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
network
low complexity
nagios CWE-306
4.3
2022-06-29 CVE-2022-29271 Incorrect Authorization vulnerability in Nagios XI
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services.
network
low complexity
nagios CWE-863
6.5
2022-06-29 CVE-2022-29272 Open Redirect vulnerability in Nagios XI
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
network
low complexity
nagios CWE-601
6.1
2021-10-14 CVE-2021-33179 Cross-site Scripting vulnerability in Nagios XI
The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting.
network
low complexity
nagios CWE-79
6.1
2021-10-05 CVE-2021-37223 Server-Side Request Forgery (SSRF) vulnerability in Nagios XI
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php.
network
low complexity
nagios CWE-918
6.5
2021-09-15 CVE-2021-38156 Cross-site Scripting vulnerability in Nagios XI
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
network
low complexity
nagios CWE-79
5.4
2021-08-13 CVE-2021-37351 Incorrect Default Permissions vulnerability in Nagios XI
Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.
network
low complexity
nagios CWE-276
5.3
2021-08-13 CVE-2021-37352 Open Redirect vulnerability in Nagios XI
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing.
network
low complexity
nagios CWE-601
6.1